Hi Patrick, Jozsef, I've been testing the following patch in my HA firewall setup with success. This patch provides better recovery in stress scenarios. Please, if you're OK with it, pass to it 2.6.38. --- Pablo Neira Ayuso (1): netfilter: nf_ct_tcp: better handling for SYN retransmissions after SYN+ACK net/netfilter/nf_conntrack_proto_tcp.c | 4 ++-- 1 files changed, 2 insertions(+), 2 deletions(-) -- To unsubscribe from this list: send the line "unsubscribe netfilter-devel" in the body of a message to majordomo@xxxxxxxxxxxxxxx More majordomo info at http://vger.kernel.org/majordomo-info.html